Suspect
d66685c1ff0ea4e93724b4e86459a8a0
PE Executable
MD5: d66685c1ff0ea4e93724b4e86459a8a0
Size: 3.49 MB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
High
| MD5 | d66685c1ff0ea4e93724b4e86459a8a0 |
| Sha1 | cf66fff1c1d02e0b19fd8faab55930d0ea499df0 |
| Sha256 | e8b13c084533e4ae24ea404d7bd849554af93071e62c61ef47f7f98cd8d62e31 |
| Sha384 | 35f153028e1cbfb5cf66bdc3c1952e63f82f35a78f6d5556a713fe1c40f771fe1e56c9ee3535d68e77fd43f937ec98b7 |
| Sha512 | 1a4f03b0b60bcce9042d50a1738c539ca9f754ef711f0c446ca8b1338660efc287a29ebb72a333b39f11b3c07c86fda7c304865c3b667d0ac00ee9d6a544ca9d |
| SSDeep | 49152:KpEgjRxxyLxdhXNPEY+XY0y0/ALL+jDjVZepRloRjXYe7ynhYMAHJbWWuuqN3ov:SNfELxbSYAoLLCZ3NYeqhYMkbRui |
| TLSH | 12F5234966D18C35CA525D3482300AB443779F993A91F383FDA83CB737B37D968A64CA |
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | server1.exe |
| Full Name | server1.exe |
| EntryPoint | System.Void server.Module2::main() |
| Scope Name | server1.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | server1 |
| Assembly Version | 1.1.0.9 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 32 |
| Main Method | System.Void server.Module2::main() |
| Main IL Instruction Count | 89 |
| Main IL | |
| Module Name | server1.exe |
| Full Name | server1.exe |
| EntryPoint | System.Void server.Module2::main() |
| Scope Name | server1.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | server1 |
| Assembly Version | 1.1.0.9 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 32 |
| Main Method | System.Void server.Module2::main() |
| Main IL Instruction Count | 89 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.